Kiteworks said it discovered and fixed a previously unknown critical security vulnerability while its systems were temporarily taken offline as a precaution against a potential cyberattack.
The company said it worked with federal intelligence authorities over the weekend as it investigated the threat and identified the vulnerability during the scheduled shutdown. According to Kiteworks, the flaw was limited to a specific capability enabled for less than 1% of its customer base.
Kiteworks developed and deployed a fix during the shutdown period and added an extra layer of protection across all of its environments. The company said there is currently no evidence that the vulnerability was exploited by attackers.
Other Kiteworks products are not affected by the vulnerability, and the company has not disclosed technical details about the flaw or how it could potentially be exploited. The vulnerability also does not have a CVE identifier at this time.
The discovery comes days after Kiteworks, formerly known as Accellion, asked customers to take their systems offline for nine hours after receiving intelligence about a potentially imminent cyberattack. The company also shut down environments it hosts on behalf of customers as a precaution.
Kiteworks said the shutdown was a preventive measure rather than a response to a confirmed breach. The recommendation to keep systems offline was lifted on September 27, 2026, after the threat window passed without any observed anomalies.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Customers have now been advised to bring their Kiteworks systems back online following the security measures and investigation.



